← Back

CVE-2015-2317

nvd nist
Published: Mar 25, 2015Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

Affected (53)

Show all products
1 product
Debian Linux
1 product
Fedora
1 product
Opensuse
1 product
Django
1 product
Solaris
1 product
Ubuntu Linux
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0
Version 22
Version 13.2
Configuration B
45 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
Up to 1.4.19
Version 1.5.10
Version 1.5.11
Version 1.5.12
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.5.4
Version 1.5.5
Version 1.5.6
Version 1.5.7
Version 1.5.8
Version 1.5.9
Version 1.5
Version 1.5 alpha
Version 1.5 beta
Version 1.6.10
Version 1.6.1
Version 1.6.2
Version 1.6.3
Version 1.6.4
Version 1.6.5
Version 1.6.6
Version 1.6.7
Version 1.6.8
Version 1.6.9
Version 1.6
Version 1.6 beta1
Version 1.6 beta2
Version 1.6 beta3
Version 1.6 beta4
Version 1.7.1
Version 1.7.2
Version 1.7.3
Version 1.7.4
Version 1.7.5
Version 1.7.6
Version 1.7 beta1
Version 1.7 beta2
Version 1.7 beta3
Version 1.7 beta4
Version 1.7 rc1
Version 1.7 rc2
Version 1.7 rc3
Version 1.8.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.2
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 10.04
Version 12.04
Version 14.04
Version 14.10

References (20)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.